PT-2023-6230 · Samba+5 · Samba+5
Kirin Van Der Veer
·
Publicado
2023-10-10
·
Atualizado
2024-11-15
·
CVE-2023-42670
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Samba (affected versions not specified)
Description
A flaw was found in Samba, making it susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes can erroneously start and compete for the same unix domain sockets, leading to partial query responses from the AD DC. This issue can cause problems such as "The procedure number is out of range" when using tools like Active Directory Users. The vulnerability is related to incorrect resource release in the RPC server, allowing a remote attacker to disrupt AD DC services by exploiting this flaw.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Improper Resource Release
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Linuxmint
Red Os
Samba
Suse
Ubuntu